LWA-2026-7222 confirmed malware
flat-logger-core@1.0.0
Malicious code in flat-logger-core (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer
Analysis
flat-logger-core@1.0.0 is a thin wrapper package (index.js re-exports simple-logger-kit) that pins its sole dependency to a non-registry URL (hxxps://artifacts[.]stg[.]yosiroute[.]com/npm/simple-logger-kit). Installing this package causes npm to fetch and execute arbitrary code from that URL at install time. The package has no repository, no description beyond "Generated package", and its only purpose is to redirect dependency resolution to an attacker-controlled endpoint.
- analyzed by
- Leitwacht
- first seen
- Jul 29, 2026, 12:01 PM
- analyzed
- Jul 29, 2026, 12:02 PM
Related advisories
- streak-cal-core@1.0.0
- streak-view-core@1.0.0
- streak-grid-core@1.0.0
- streak-daykey-lib@1.0.0
- streak-int-lib@1.0.0
- test22221@2.2.7
- nagixjs@2.1.6
- postcss-motion-utils@3.2.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.